PT-2026-96833 · Nuclei · Nuclei

CVE-2026-76802

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nuclei versions 3.0.0 through 3.9.9
Description The DAST template loading branch fails to apply the unsigned code-template signature check before accepting a template that contains both a fuzzing: block and an unsigned code: block. When the -dast flag is enabled, an untrusted multiprotocol template can place an unsigned code request into the execution queue, allowing the execution of arbitrary shell commands. This bypasses the cryptographic signature requirement and the -code flag normally required for code: protocol templates. The issue affects CLI DAST scans and SDK integrations that enable DAST while accepting attacker-supplied templates.
Recommendations Update Nuclei to version 3.10.0. Avoid running DAST scans with untrusted templates. Do not use the -dast flag with templates from unverified sources.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76802
GHSA-JPF4-98QJ-QR67

Affected Products

Nuclei